Security design
Why the backup survives the incident that takes production down.
View as MarkdownA copy is only external if it is under different keys, in different storage, on a different trust boundary, and the compromised system has no route to it and no permission to delete it. Every design decision in this section is that sentence applied somewhere.
The three claims, and where each is proven
| Claim | Proven by |
|---|---|
| We cannot read your local backups | Encryption: the key is applied on your machine and we never hold the private half |
| A stolen credential of yours cannot reach the archive | Permissions: the enforcement atom is the permission, and worker keys carry two |
| You can tell what happened | Audit log: append-only, with the actor on every row |
The parts
Threat model
The attacker this design assumes: whoever holds your production access.
Encryption
Client-side on the local path, with a key we never hold.
Key management
You keep the private half. Loss is unrecoverable, deliberately.
Data flow
Bulk data moves directly to object storage. Only metadata passes through us.
Authentication
How people and machines prove who they are.
API keys
Machine credentials, what they may hold, and what they may not.
Permissions
The permission, not the role, is what the backend enforces.
Audit log
Every mutation recorded, with the actor that performed it.
Compliance
What we do, and what we do not claim.
Disclosure
Reporting a vulnerability.
What this section is not
It is a description of how the system works, not a marketing page and not a certification. Where a control is weaker than it sounds, the page says so in the same paragraph as the control. The two places that matters most today:
- Artifact locks are enforced by us, not by the storage layer. See retention.
- Encryption is optional, and nothing refuses to run without it. See encryption.
If you are evaluating us against a requirement, read the threat model first. It is the page that says what we do not defend against.